APIRL: Deep Reinforcement Learning for REST API Fuzzing
Myles Foley, Sergio Maffeis
Abstract
REST APIs have become key components of web services. However, they often contain logic flaws resulting in server side errors or security vulnerabilities. HTTP requests are used as test cases to find and mitigate such issues. Existing methods to modify requests, including those using deep learning, suffer from limited performance and precision, relying on undirected search or making limited usage of the contextual information. In this paper we propose APIRL, a fully automated deep reinforcement learning tool for testing REST APIs. A key novelty of our approach is the use of feedback from a transformer module pre-trained on JSON-structured data, akin to that used in API responses. This allows APIRL to learn the subtleties relating to test outcomes, and generalise to unseen API endpoints. We show APIRL can find significantly more bugs than the state-of-the-art in real world REST APIs while minimising the number of required test cases. We also study how reward functions, and other key design choices, affect learnt policies with a thorough ablation study.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 0713cc39-fecb-4d5e-a77f-2ac7ffdfdd7aCited by top-tier papers2
- DRMD: Deep Reinforcement Learning for Malware Detection Under Concept DriftShae McFadden, Myles Foley, Mario D'Onghia, Chris Hicks et al.AAAI 2026 · 7 citations
- SoK: The Pitfalls of Deep Reinforcement Learning for CybersecurityShae McFadden, Myles Foley, Elizabeth Bates, Ilias Tsingenopoulos et al.USENIX Security 2026 · 7 citations
Builds on12
- Coverage-based Greybox Fuzzing as Markov ChainMarcel Böhme, Van-Thuan Pham, Abhik RoychoudhuryCCS 2016 · 1,026 citations
- Stabilizing Transformers for Reinforcement LearningEmilio Parisotto, H. Francis Song, Jack W. Rae, Razvan Pascanu et al.ICML 2020 · 464 citations
- Automatic Web Testing Using Curiosity-Driven Reinforcement LearningYan Zheng, Yi Liu, Xiaofei Xie, Yepang Liu et al.ICSE 2021 · 75 citations
- Automated test generation for REST APIs: no time to rest yetMyeongsoo Kim, Qi Xin, Saurabh Sinha, Alessandro OrsoISSTA 2022 · 67 citations
- Intelligent REST API data fuzzingPatrice Godefroid, Bo-Yuan Huang, Marina PolishchukFSE 2020 · 57 citations
Related papers
- DeepREST: Automated Test Case Generation for REST APIs Exploiting Deep Reinforcement LearningDavide Corradini, Zeno Montolli, Michele Pasqua, Mariano CeccatoASE 2024 · 13 citations
- Adaptive REST API Testing with Reinforcement LearningMyeongsoo Kim, Saurabh Sinha, Alessandro OrsoASE 2023 · 29 citations
- A Multi-Agent Approach for REST API Testing with Semantic Graphs and LLM-Driven InputsMyeongsoo Kim, Tyler Stennett, Saurabh Sinha, Alessandro OrsoICSE 2025 · 4 citations
- Generating API Parameter Security Rules with LLM for API Misuse DetectionJinghua Liu, Yi Yang, Kai Chen, Miaoqian LinNDSS 2025
- SQIRL: Grey-Box Detection of SQL Injection Vulnerabilities Using Reinforcement LearningSalim Al Wahaibi, Myles Foley, Sergio MaffeisUSENIX Security 2023
